|
246931
|
7.2 |
HIGH
Network
|
apache
|
virtual_computing_lab
|
Apache VCL versions 2.1 through 2.5 do not properly validate form input when adding and removing VMs to and from hosts. The form data is then used in SQL statements. This allows for an SQL injection …
|
CWE-89
SQL Injection
|
CVE-2018-11774
|
2024-11-21 12:44 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246932
|
9.8 |
CRITICAL
Network
|
apache
|
virtual_computing_lab
|
Apache VCL versions 2.1 through 2.5 do not properly validate form input when processing a submitted block allocation. The form data is then used as an argument to the php built in function strtotime.…
|
CWE-20
Improper Input Validation
|
CVE-2018-11773
|
2024-11-21 12:44 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246933
|
7.2 |
HIGH
Network
|
apache
|
virtual_computing_lab
|
Apache VCL versions 2.1 through 2.5 do not properly validate cookie input when determining what node (if any) was previously selected in the privilege tree. The cookie data is then used in an SQL sta…
|
CWE-89
SQL Injection
|
CVE-2018-11772
|
2024-11-21 12:44 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246934
|
9.8 |
CRITICAL
Network
|
apache
|
storm
|
In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Ja…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2018-11779
|
2024-11-21 12:44 |
2019-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246935
|
7.2 |
HIGH
Network
|
elitecms
|
elite_cms
|
An issue was discovered in Elite CMS Pro 2.01. In /admin/add_sidebar.php, the ?page= parameter is vulnerable to SQL injection.
|
CWE-89
SQL Injection
|
CVE-2018-12250
|
2024-11-21 12:44 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246936
|
9.8 |
CRITICAL
Network
|
qualcomm
|
mdm9150_firmware mdm9206_firmware mdm9607_firmware mdm9640_firmware mdm9650_firmware msm8909w_firmware msm8996au_firmware qca6174a_firmware qca6574au_firmware qca9377_firmw…
|
Lack of check on length of reason-code fetched from payload may lead driver access the memory not allocated to the frame and results in out of bound read in Snapdragon Auto, Snapdragon Consumer Elect…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-11955
|
2024-11-21 12:44 |
2019-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246937
|
5.5 |
MEDIUM
Local
|
qualcomm
|
ipq8064_firmware mdm9150_firmware mdm9206_firmware mdm9607_firmware mdm9640_firmware mdm9650_firmware msm8996au_firmware qca6174a_firmware qca6574au_firmware qca9377_firmwa…
|
The txrx stats req might be double freed in the pdev detach when the host driver is unloading in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Ind…
|
CWE-415
Double Free
|
CVE-2018-11947
|
2024-11-21 12:44 |
2019-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246938
|
5.5 |
MEDIUM
Local
|
qualcomm
|
ipq4019_firmware ipq8064_firmware ipq8074_firmware mdm9150_firmware mdm9206_firmware mdm9607_firmware mdm9640_firmware mdm9650_firmware msm8996au_firmware qcs405_firmware
|
Failure to initialize the reserved memory which is sent to the firmware might lead to exposure of 1 byte of uninitialized kernel SKB memory to FW in Snapdragon Auto, Snapdragon Consumer IOT, Snapdrag…
|
CWE-200
Information Exposure
|
CVE-2018-11942
|
2024-11-21 12:44 |
2019-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246939
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9150_firmware mdm9206_firmware mdm9607_firmware mdm9640_firmware mdm9650_firmware msm8909w_firmware qca6574au_firmware sd_210_firmware sd_212_firmware sd_205_firmware
|
Use after issue in WLAN function due to multiple ACS scan requests at a time in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9150, MDM9206, MDM9607, MD…
|
CWE-416
Use After Free
|
CVE-2018-11939
|
2024-11-21 12:44 |
2019-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246940
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9150_firmware mdm9206_firmware mdm9607_firmware mdm9640_firmware mdm9650_firmware msm8996au_firmware qca6174a_firmware qca6574au_firmware qca9377_firmware qca9379_firmwa…
|
Possible out of bounds write due to improper input validation while processing DO_ACS vendor command in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdra…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-11934
|
2024-11-21 12:44 |
2019-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|